The number of illegal accesses and DoS(Denial of Service)or DDoS(Distributed DoS)attacks are increasing as popularization of Internet. In these attacks, the source IP address is sometimes manipulated, so it is difficult to identify the original source IP address. IP trace back technique by departure stamp in edge routers is a nice way to identify the original source IP address of attackers, and can reduce network load. However, it require high performance for edge router because it stamps all packets through the edge router. In this paper, we propose a method that stamps the limited number of packets that may participate DoS or DDoS attack. We implement proposed method and confirm that our method can reduce the load on edge router.